Activity timeline
Safepay appears in 3 tracked threats between and ; the busiest month was 2026-03 with 1 report.
ATT&CK techniques observed
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 3 of 3 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 3 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 3 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1039 Data from Network Shared Drive — Collectionobserved in 2 of 3 tracked threats
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol — Exfiltrationobserved in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 2 of 3 tracked threats
- T1072 Software Deployment Tools — Executionobserved in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1078.002 Domain Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 2 of 3 tracked threats
- T1135 Network Share Discovery — Discoveryobserved in 2 of 3 tracked threats
Tracked threats
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data ExfiltrationHIGH
- Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)HIGH
- Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider, Double-Extortion Data Theft via VPN Credential AbuseHIGH